|
|
Your daily, AI-assisted cybersecurity intelligence brief.
|
|
|
|
Today's report
|
|
Source: Security Rabbits
|
The Rabbit's Foot (TLDR)
|
|
Citrix NetScaler Zero-Day Exploited to Deploy Web Shells
Attackers are exploiting CVE-2026-88772 (related to CVE-2026-88771) to gain root access, steal credentials, and move laterally. Apply Citrix's latest patches immediately.
|
|
|
Apple Patches CoreGraphics Zero-Day Under Active Exploitation
CVE-2026-86950 is an out-of-bounds write in CoreGraphics exploited in sophisticated targeted attacks. Update iOS, macOS, and iPadOS to the latest versions.
|
|
|
Critical Unauthenticated RCE in Balbooa Forms for Joomla
Balbooa Forms < 2.4.3.4 allows unauthenticated remote code execution via field shortcode injection. Update to 2.4.3.4 or later immediately.
|
|
|
HPE Networking Instant ON: Unauthenticated Remote Buffer Overflow
A critical buffer overflow allows arbitrary code execution as a privileged user. Apply HPE firmware updates urgently due to widespread deployment.
|
|
|
Star Blizzard Targets 100+ Organizations with Fake Event Invites
Russian state hackers use fake event invitations to deliver a Windows backdoor. Warn users and strengthen email filtering and endpoint detection.
|
|
| Source: CVE Trend
|
Trending vulnerability
|
|
|
Citrix NetScaler ADC and Citrix NetScaler Gateway
|
Published:
Updated:
|
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway..This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading ..
|
|
| Source: CISA
|
CISA exploits
|
|
|
Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.(2026-09-29)
|
|
| Source: NIST
|
NIST CVE
|
|
|
Unauthenticated remote code execution via field shortcode injection in Balbooa Forms < 2.4.3.4. Any Joomla site running this popular form builder with the PHP-after-submission action enabled is at immediate risk; update to 2.4.3.4 or later.
|
|
|
|
Unauthenticated arbitrary file write leading to remote code execution in the gmfeed module for PrestaShop. Attackers can write and execute PHP via feed.php; upgrade to version 2.3.9 immediately.
|
|
|
|
Missing authentication in the PUT /user/updatePwd endpoint allows unauthenticated attackers to reset any storefront account password and take over accounts. Patch or restrict access to this endpoint immediately.
|
|
|
|
Unauthenticated remote buffer overflow allowing arbitrary code execution as a privileged user on the underlying OS. Given the widespread deployment of Instant ON APs, apply HPE firmware updates urgently.
|
|
|
|
The default blockUnsafeOperationsPlugin fails to classify trailer..cmd as unsafe, allowing attacker-controlled config to execute shell commands with Node.js process privileges. Upgrade to simple-git 4.0.1 or later.
|
|
|
|
parseEnv omits VISUAL from GitEnvKeys, letting attacker-influenced environment values invoke an arbitrary editor and execute code. Upgrade argv-parser to 2.0.1 or later.
|
|
|
|
Attacker-chosen heap corruption via masked WebSocket frames split across packets, enabling remote code execution or crash in embedded devices. Apply the latest NetX Duo patches from Eclipse ThreadX.
|
|
|
|
News
|
|
|
24-Year-Old Arrested in Dutch Investigation Into ShinyHunters
Dutch police confirm the arrest of a 24-year-old Amsterdam man as part of an investigation into the ShinyHunters hacking group. Dutch police confirmed this week that a 24-year-old man from Amsterdam was arrested earlier this month as part of an [...] (Security Affairs)
|
|
|
|
Three Million Affected in Pentagon Personnel Agency Data Breach
Pentagon personnel agency breach exposed data of 3 million people after attackers accessed a file-sharing server for about nine months. The U.S. Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense, is [...] (Security Affairs)
|
|
| Source: Ransomware.live
|
Ransomware attacks
|
|
|
Gibson Area Hospital & Health Services
|
|
|
|
oterolaw.com \\ cpacb.com \\ somasolucoes.com \\ noonsugar.com \\ iccsi.com \\ intense.pl
|
|
|
|
camorim.com.br \\ spg.co.kr
|
|
|
|
AHeadStart Tutoring \\ Crowder Industries, Inc
|
|
|
|
advantech.com \\ carolinaasthma.com
|
|
|
|
trailerbridge.com \\ wildmanbg.com \\ northeastrehab.com \\ mulholland.com \\ mccordclaims.com \\ maxwell-group.com \\ latitudesubro.com \\ goriteway.com
|
|
|
|
Paid Victim 32373FFB7AF7E725
|
|
|
|